/*
package cn.ym.mall.filter;

import cn.cyh.news.entity.User;

import javax.servlet.*;
import javax.servlet.annotation.WebFilter;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import javax.servlet.http.HttpSession;
import java.io.IOException;

//@WebFilter(urlPatterns = {"/admin/*","*.do"})
@WebFilter(urlPatterns = {"/admin/*"})
public class AdminFilter implements Filter {
    @Override
    public void init(FilterConfig filterConfig) throws ServletException {
        System.out.println("管理权限过滤器开启");
    }

    @Override
    public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException {
        HttpServletRequest request = (HttpServletRequest) servletRequest;
        HttpSession session = request.getSession();
        if (request.getServletPath().startsWith("/user.do") && (request.getParameter("opr").equals("login") || request.getParameter("opr").equals("loginOut"))) {
            filterChain.doFilter(servletRequest, servletResponse);
        }else if (session.getAttribute("loginUser") == null) {
                HttpServletResponse response = (HttpServletResponse) servletResponse;
                response.sendRedirect("/index.jsp");
        }else if (((User) session.getAttribute("loginUser")).getUrole() == 1){
            HttpServletResponse response = (HttpServletResponse) servletResponse;
            response.sendRedirect("/index.jsp");
        }else if (((User) session.getAttribute("loginUser")).getUrole() == 2){
            filterChain.doFilter(servletRequest, servletResponse);
        }
    }

    @Override
    public void destroy() {
        System.out.println("管理权限过滤器销毁");
    }
}
*/
